This is an old revision of the document!
OnlyOffice
This tutorial is for Debian users who wish to spin up an Only Office container using podman. It presumes you have a Cockpit container VM/host setup already. If not, head over to Cockpit before you start here. Once podman is setup and you have a dedicated rootless user, you can proceed. To begin with, let's setup a directory for this container and generate our jwt secret:
mkdir -p ~/onlyoffice/{data,logs,lib,db}
umask 077
openssl rand -hex 32 | tee ~/onlyoffice/jwt.secret
chmod 600 ~/onlyoffice/jwt.secret
Placeholder used below:
JWT_SECRET=replace-with-your-jwt-secret
systemctl --user disable --now container-onlyoffice.service 2>/dev/null || true rm -f ~/.config/systemd/user/container-onlyoffice.service podman rm -f onlyoffice mkdir -p ~/.config/containers/systemd cat > ~/.config/containers/systemd/container-onlyoffice.container << 'EOF' [Container] ContainerName=onlyoffice Image=docker.io/onlyoffice/documentserver:latest PublishPort=127.0.0.1:8082:80 Environment=JWT_ENABLED=true Environment=JWT_SECRET=replace-with-your-jwt-secret Environment=JWT_HEADER=Authorization Environment=ALLOW_PRIVATE_IP_ADDRESS=false Volume=/home/worker/onlyoffice/logs:/var/log/onlyoffice:Z Volume=/home/worker/onlyoffice/data:/var/www/onlyoffice/Data:Z Volume=/home/worker/onlyoffice/lib:/var/lib/onlyoffice:Z Volume=/home/worker/onlyoffice/db:/var/lib/postgresql:Z Volume=/home/worker/podman-local/volumes/84a360c1a5dd357b0cfe5af71a59f7338eeca694336b1ea8bef5d5c41fe7deb7/_data:/usr/share/fonts/truetype/custom:Z PodmanArgs=--cpus=4 --memory=8g [Service] Restart=always TimeoutStopSec=120 [Install] WantedBy=default.target EOF systemctl --user daemon-reload systemctl --user reset-failed container-onlyoffice.service systemctl --user start container-onlyoffice.service
WantedBy=default.target starts it. Do not systemctl enable a Quadlet unit. Do not podman generate systemd.
Drop the fonts Volume= line if you have no custom fonts.
JWT header must be Authorization, not AuthorizationJwt.
sleep 90
systemctl --user is-active container-onlyoffice.service
podman inspect onlyoffice --format '{{.Name}} cpus={{.HostConfig.NanoCpus}} memory={{.HostConfig.Memory}}'
curl -sS -o /dev/null -w '%{http_code}\n' http://127.0.0.1:8082/healthcheck
podman exec onlyoffice supervisorctl status
Expect active, cpus=4000000000, memory=8589934592, HTTP 200, and ds:converter / ds:docservice RUNNING. First start takes about 90 seconds.
/usr/local/bin/upgrade-onlyoffice.sh. A tag change is an edit to Image= in the .container file before daemon-reload. The script does not recreate the unit.
#!/bin/bash
set -euo pipefail
podman pull docker.io/onlyoffice/documentserver:latest
systemctl --user stop container-onlyoffice.service
systemctl --user daemon-reload
systemctl --user reset-failed container-onlyoffice.service
systemctl --user start container-onlyoffice.service
sleep 90
curl -sS -o /dev/null -w '%{http_code}\n' http://127.0.0.1:8082/healthcheck
Run it as worker:
su - worker -c '/bin/bash /usr/local/bin/upgrade-onlyoffice.sh'
Do not sudo -u worker. That drops the session bus.
a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl
/etc/apache2/sites-available/files.haacksnetworking.org.conf:
<VirtualHost *:80>
ServerName files.haacksnetworking.org
RewriteEngine On
RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>
<VirtualHost *:443>
ServerName files.haacksnetworking.org
SSLEngine on
SSLCertificateFile /etc/letsencrypt/live/files.haacksnetworking.org/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/files.haacksnetworking.org/privkey.pem
Include /etc/letsencrypt/options-ssl-apache.conf
SetEnvIf Host "^(.*)$" THE_HOST=$1
RequestHeader setifempty X-Forwarded-Proto "https"
RequestHeader setifempty X-Forwarded-Host %{THE_HOST}e
ProxyAddHeaders Off
ProxyPreserveHost On
RewriteEngine On
RewriteCond %{HTTP:Upgrade} websocket [NC]
RewriteCond %{HTTP:Connection} upgrade [NC]
RewriteRule ^/?(.*) "ws://127.0.0.1:8082/$1" [P,L]
ProxyPass / http://127.0.0.1:8082/
ProxyPassReverse / http://127.0.0.1:8082/
ErrorLog ${APACHE_LOG_DIR}/onlyoffice-error.log
CustomLog ${APACHE_LOG_DIR}/onlyoffice-access.log combined
</VirtualHost>
a2ensite files.haacksnetworking.org.conf apache2ctl configtest && systemctl reload apache2 curl -sI https://files.haacksnetworking.org/healthcheck
Admin → ONLYOFFICE:
https://files.haacksnetworking.org~/onlyoffice/jwt.secret
JWT header must be Authorization.
— oemb1905 2026/10/10 03:15